VYPR

Import WP

by WordPress

CVEs (1)

  • CVE-2026-14925Aug 12, 2026
    risk 0.00cvss epss

    The Import WP WordPress plugin before 2.14.23 does not perform any authorization check on one of its export-file download handlers, allowing unauthenticated attackers to download export files generated by administrators, which may contain user personal data such as email…